> Markdown version of [/jobs/ext/1999211-director-global-it-security](https://www.wearedevelopers.com/jobs/ext/1999211-director-global-it-security). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Director Global IT Security - **Company:** EVENTIM - **Location:** Hamburg, Germany - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Application Programming Interfaces (APIs), Artificial Intelligence, Software as a Service, Cyber Security, Continuous Integration, Information Leak Prevention, DDoS Mitigation, Identity and Access Management, Integrated Development Environments, Information Systems Security Architecture Professional, Systems Development Life Cycle, Cloud Services, Secure Coding, Software Vulnerability Management, Enterprise Software Applications, Software Security, Rate Limiting, Information Technology, Integration Frameworks, Hardware Infrastructure, Cts+, Devsecops, Security Orchestration, Automation & Response - **Published:** August 9, 2026 - **Apply:** https://www.adzuna.de/details/5833610468 ## About the Role * At least 10 years of experience in cybersecurity, information security or IT security, including significant leadership responsibility in a technology-driven, high-scale or digital platform environment. * Proven experience leading security across complex IT landscapes covering customer-facing platforms, APIs, cloud services, on-premises infrastructure, enterprise systems, identity platforms and software development environments. * A strong track record in building or maturing security functions across Product Security, Enterprise Security, GRC and Security Operations. * Deep expertise in application and product security, enterprise security, identity and access management, vulnerability management, secure architecture, incident response and security monitoring. * Strong practical understanding of DevSecOps, secure SDLC, software supply chain security, developer enablement and security automation. * Experience protecting high-traffic websites, e-commerce, marketplaces, ticketing platforms, SaaS products or similarly business-critical consumer platforms, including hands-on familiarity with bot management and automated abuse defence. * Experience applying AI and machine learning to cyber defence, combined with an understanding of AI-specific security risks such as prompt injection, data leakage, adversarial manipulation and model or vendor risk. * The ability to work credibly with senior engineers and architects while communicating effectively with executives, business leaders and non-technical stakeholders. Excellent English communication skills are required; German is highly advantageous., You see security as an enabler of trust, resilience and innovation. You combine strategic thinking with hands-on pragmatism, build strong bridges with Engineering and Product, create guardrails that teams actually adopt and remain calm and structured under pressure. A degree in Computer Science, Information Security, Information Technology, Engineering or a related discipline is preferred, while equivalent practical experience is equally valued. Certifications such as CISSP, CISM, CISA, CCSP, GIAC or ISO 27001 Lead Implementer/Lead Auditor are advantageous. ## Description As Director Global IT Security (m/f/d), you will lead the continuous hardening of CTS EVENTIM's group-wide technology landscape and shape the next stage of our security maturity across technology, people and processes. Reporting directly to the CTO, you will own and further develop the security function across Product Security, Enterprise Security, Governance, Risk & Compliance (GRC) and Security Operations. A key focus will be strengthening shift-left security across Engineering and Product. You will establish developer-friendly guardrails, practical security standards and strong security capabilities within engineering teams, while protecting high-traffic ticketing platforms against bot attacks, automated abuse and other adversarial traffic patterns., * Define and execute a group-wide IT security strategy and roadmap aligned with business goals, technology strategy and international growth. * Drive the hardening of customer-facing platforms, B2B and SaaS products, enterprise systems, cloud services, infrastructure, identity platforms, APIs, development environments and third-party integrations. * Build and mature the security operating model across Product Security, Enterprise Security, GRC and Security Operations, including policies, controls, risk management and measurable outcomes. * Establish practical DevSecOps and shift-left capabilities, including secure coding, threat modelling, security champions, code and infrastructure scanning, CI/CD security and secure release gates. * Lead the security approach for high-traffic, business-critical ticketing platforms, including bot management, WAF/CDN controls, DDoS protection, rate limiting, behavioural analytics, anomaly detection and incident playbooks. * Lead Security Operations and incident readiness, including monitoring, detection engineering, escalation paths, exercises, post-incident reviews and continuous improvement. * Own the security-related GRC agenda and support compliance and audit readiness in line with relevant frameworks and regulations, including ISO 27001, NIST CSF, GDPR and NIS2-related expectations. * Shape the responsible use of AI in cyber defence and security operations, while establishing appropriate governance, human oversight, auditability and safeguards for sensitive information. * Lead, develop and scale the IT Security team and strengthen security awareness and behaviour across the organisation., This role offers the opportunity to shape group-wide security in one of the most dynamic technology environments in live entertainment. You will work at the heart of live entertainment and technology, protecting platforms used by millions of fans and developing a strategically important security function with broad organisational visibility. CTS EVENTIM is committed to an inclusive working environment where people of all backgrounds can contribute, grow and do their best work. ## Related Videos - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Rate-limiting using eBPF and Istio: How to protect your SaaS customers from themselves](https://www.wearedevelopers.com/videos/100220-rate-limiting-using-ebpf-and-istio-how-to-protect-your-saas-customers-from-themselves) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [DevSecOps: Security in DevOps](https://www.wearedevelopers.com/videos/36-devsecops-security-in-devops) - [DevSecOps culture](https://www.wearedevelopers.com/videos/783-devsecops-culture) ## Related Articles - [Finding IT & Technology English-speaking Jobs in Germany ](https://www.wearedevelopers.com/magazine/446-finding-it-technology-english-speaking-jobs-in-germany) - [IT Salaries in Germany](https://www.wearedevelopers.com/magazine/287-it-salaries-in-germany) - [The Most Popular IT Jobs on the Market](https://www.wearedevelopers.com/magazine/376-the-most-popular-it-jobs-on-the-market) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies)